Google Cloud Armor
Google Cloud Armor applies web application firewall (WAF) and IP rules to traffic at Google's external load balancers, before it reaches a backend. The GCP Web App Blueprint gives each stage two security policies built from one rule template the GCP Enterprise Baseline publishes, and the Baseline can add organization-wide edge rules above them.
What it does
A security policy is an ordered list of rules, each a match expression, an action (allow, deny, or a rate-based ban) and a priority; the lowest priority number that matches decides, and evaluation stops there. Preconfigured WAF rules detect attack classes such as SQL injection and cross-site scripting at a chosen sensitivity. A rule in preview is evaluated and logged without being enforced. Adaptive Protection detects layer 7 DDoS (distributed denial of service) attacks. A hierarchical security policy attached to a folder is evaluated before the policies of the projects beneath it, and is part of Cloud Armor Enterprise.
How BuiltForProd uses it
The rule template. The Baseline keeps one template, policies/cloud-armor-template.json, and the pm-publish unit publishes it to every stage as the JSON parameter waf--policy-template of Parameter Manager. A change to policies/ needs the security team's review (CODEOWNERS).
{
"preconfigured_rules": [
"sqli-v33-stable",
"xss-v33-stable",
"lfi-v33-stable",
"rfi-v33-stable",
"rce-v33-stable",
"methodenforcement-v33-stable",
"scannerdetection-v33-stable",
"protocolattack-v33-stable",
"sessionfixation-v33-stable"
],
"sensitivity": 1,
"rate_limit": {
"count": 300,
"interval_sec": 60,
"ban_duration_sec": 600
},
"adaptive_protection": true,
"default_action": "allow"
}
The stage policies. The Web App Blueprint renders the template into two policies per stage, one on the API's load balancer and one on the single-page front end's load balancer (acme-usw1-prd-api-armor and acme-usw1-prd-frontend-armor in prod). The rules run in this order:
| Priority | Rule | Preview |
|---|---|---|
| 950 | Deny (403) the CVE signatures of cve-canary, Log4Shell included | never |
| 1000+ | Deny (403), one rule per preconfigured WAF rule set, sensitivity 1 | armor_preview |
| 2000 | Rate-based ban per client IP: over 300 requests in 60 seconds is banned for 600 seconds (429) | armor_preview |
| default | Allow | never |
The deny rules come first because a request under the rate limit matches the ban rule's conform action, allow, which ends evaluation; for the same reason a request a WAF rule denies never counts toward the rate limit, and custom deny rules belong below 2000. armor_preview is true in dev, so false positives are collected before anything is blocked, and false in staging and prod. Adaptive Protection is on. The list prices in the code comment are $5 per policy and $1 per rule per month, plus $0.75 per million requests, on Cloud Armor Standard.
Organization-wide edge rules (optional). With enable_cloud_armor_enterprise = true in security.hcl, off by default, the cloud-armor-org unit attaches the hierarchical policy acme-plat-edge to the plat folder: Google Threat Intelligence deny rules for Tor exit nodes and known malicious IPs, and optional geo and IP deny lists. Requests no rule matches continue to the stage policy. Attaching it enrolls every stage project in Cloud Armor Enterprise, pay-as-you-go by default or the annual subscription ($3,000 per month per organization).
Network-level rules for traffic inside the VPCs are a separate layer, the Cloud NGFW firewall policies.
Terms you will see
| Term | Meaning |
|---|---|
| Security policy | The ordered rule list attached to a load balancer's backend. |
| Preconfigured WAF rule | A Google-maintained rule set such as sqli-v33-stable. |
| Preview | Evaluate and log a rule without enforcing it. |
| Rate-based ban | Deny a client that exceeds a request rate, for a ban period. |
waf--policy-template | The contract parameter carrying the Baseline's rule template. |
| Hierarchical policy | A folder-level policy evaluated before the project policies. |
Where to read more
- GCP Web App Blueprint overview and the GCP Enterprise Baseline overview.
- Cloud NGFW firewall policies for the network rules beneath the edge.
- Defense in depth for layering edge and network controls.